CVE-2024-37058
EUVD-2024-203004.06.2024, 12:15
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lfprojects | mlflow | 2.5.0 ≤ |
𝑥
= Vulnerable software versions
Common Weakness Enumeration